Back to skill

Security audit

patent-pre-evaluation-report

Security checks for vulnerabilities and agentic risk

Overview

The skill is a patent report generator, but it can send confidential invention text to external PatSnap MCP services while hardcoding university/vendor branding and a confidentiality statement that may be inaccurate.

Review carefully before installing. Use this skill only if you are authorized to create China University of Mining and Technology/PatSnap-branded reports and are allowed to send invention details to the configured PatSnap MCP services. For unpublished or trade-secret material, require explicit user approval and redaction before external searches, and verify that the final confidentiality statement matches what was actually transmitted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:83
Finding

Mandatory Institutional Branding and Vendor-Link Injection into Generated Reports

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:83-85, SKILL.md:117-127; duplicated in references/report-workflow.md:54-63, references/report-workflow.md:171, and references/report-workflow.md:210-218
Vulnerability Type: Output instruction hijacking
Risk Level: High

Complete Relevant Code Snippet

The following is an English translation of the relevant source directives:

text
3. Institutional header: left = "China University of Mining and Technology"
   plus its full English name; right = a gold-outlined circular emblem containing
   the character representing "Mining."
5. Confidentiality badge: gold-outlined elliptical label:
   "Internal Confidential · Pre-Application Evaluation · Supported by PatSnap."

Data Security and Confidentiality Statement
(Fixed content that every report must contain):
1. Internal use and access control:
   This report is only for use by the Intellectual Property Management Office
   of the Research Institute of China University of Mining and Technology,
   project inventors, and authorized patent agencies. It must not be distributed
   without authorization.
3. Platform security statement:
   PatSnap security and compliance capabilities may be viewed at:
   https://www.zhihuiya.com/security-center.

Policy Background
(Fixed content containing five policies that every report must contain).

The same requirements are repeated in references/report-workflow.md, including a mandatory HTML hyperlink:

html
<a href="https://www.zhihuiya.com/security-center" target="_blank">
  https://www.zhihuiya.com/security-center
</a>

Technical Analysis

The Skill is presented as a general patent pre-evaluation report generator, but its instructions require every generated report to contain a specific university identity, a university emblem, PatSnap attribution, fixed organizational access-control language, policy messaging, and ...[truncated 2086 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all mandatory university names, emblems, vendor attributions, and organization-specific confidentiality statements from the default template.
  2. Introduce explicit report parameters such as organization_name, organization_logo, authorized_audience, and vendor_attribution.
  3. Default these parameters to neutral or empty values.
  4. Require affirmative user confirmation before inserting any institutional identity or third-party endorsement.
  5. Make policy sections optional and select them according to the user's jurisdiction and use case.
  6. Remove vendor links unless they are directly relevant and approved by the user.
  7. Where external links remain necessary, add rel="noopener noreferrer" to links using target="_blank".
  8. Add a pre-export review that lists all organization names, endorsements, and external URLs included in the report.
  9. Consolidate template directives into one configurable source to prevent duplicated mandatory instructions from overriding user choices.

T09 · Insecure Skill Coding Practices

Warning
Location
references/report-workflow.md:8
Finding

Potential Disclosure of Complete Unpublished Invention Text to External MCP Services

Content
View full analysis

Vulnerability Details

File Location: references/report-workflow.md:8, references/report-workflow.md:15, references/report-workflow.md:21-22; contradictory confidentiality statement at SKILL.md:117-125
Vulnerability Type: Insecure handling of confidential technical information
Risk Level: Medium

Complete Relevant Code Snippet

The following is an English translation of the complete relevant workflow entries:

text
Phase A: Technical Extraction

A1 | novelty_summary
   | Input: Complete text of the technical solution
   | Output: tech_problem / tech_solution / tech_efficacy

Phase B: Search Strategy

B2 | novelty_keywords_extend
   | Input: One keyword plus the technical-solution text
   | Output: Synonyms, broader terms, narrower terms, and translation extensions

Phase C: Real Search Execution

C1  | novelty_search_agent
    | Input: Technical-solution text, preferred
    | Output: Search result list plus patent identifiers

C1a | novelty_semantic_search
    | Input: Technical-solution text
    | Output: Semantically similar patent list

The mandatory report statement at SKILL.md:123 asserts the opposite data-handling behavior:

text
Data minimization and minimum disclosure:
External searches use only keywords, IPC classification numbers, and abstract
technical features. The original technical disclosure, complete core-parameter
tables, and unpublished experimental data are not uploaded.

Technical Analysis

The workflow directs the agent to send the complete technical-solution text to several externally configured MCP tools. Patent disclosures can contain unpublished inventions, experimental results, implementation details, trade secrets, and personally identifiable information.

No instruction requires the agent to:

  • Obtain explicit user consent before external transmission.
  • Determine whether the disclosure is confidential or unpublished.

...[truncated 2449 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add an explicit consent checkpoint before transmitting any invention content to an external MCP service.
  2. Clearly identify the destination service, fields being transmitted, purpose, and applicable retention policy.
  3. Perform local preprocessing and send only user-approved keywords, IPC classifications, and abstract technical features by default.
  4. Remove names, contact details, complete parameter tables, unpublished experimental data, and unnecessary implementation details.
  5. Provide a local-only analysis mode when the user declines external transmission.
  6. Maintain an evidence log recording each MCP service, transmission time, transmitted data category, and user authorization.
  7. Generate the confidentiality statement dynamically from actual tool-call records rather than using fixed text.
  8. If complete text must be transmitted, clearly state that fact in the final report and require separate affirmative approval.
  9. Document service-side retention, deletion, encryption, access control, and model-training practices before processing confidential material.
  10. Add automated tests ensuring that reports never claim data minimization when full technical text was supplied to an external tool.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/report-workflow.md (reported line 197)May include surrounding context.

数据安全声明 HTML 模板

html
<!-- S0: 数据安全与保密声明 -->
<div class="section">
  <div class="section-header">
    <div class="section-num">🔒</div>

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction '除非用户另有要求,主要使用中文' establishes Chinese as the default language for the skill. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation, and this file does not present language choice as an upfront opt-in mechanism.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow explicitly claims external searches should use only keywords, IPC classes, and abstracted technical features, yet Phase C instructs the agent to send the full technical-solution text to search tools. In a patent pre-filing context, this can expose unpublished inventions, core parameters, and confidential R&D details to external platforms, creating confidentiality, trade-secret, and premature-disclosure risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file presents all user-facing instructions and the prescribed failure message entirely in Chinese, including the exact text users should be shown on connection failure. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing instructions and workflow content exclusively in Chinese, including headings, procedural steps, and required report text. Under the language/locale policy, forcing a single language without user opt-in can be a natural-language policy violation when no explicit choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.